From b67f66b09ca7ef793590948934071a5f21513007 Mon Sep 17 00:00:00 2001 From: Tomasz Leman Date: Mon, 5 Oct 2026 12:32:56 +0200 Subject: [PATCH] audio: data_blob: fail gracefully on oversized SET fragment comp_data_blob_set_cmd() reassembles a host-provided blob from multiple SOF_IPC_COMP_SET_DATA fragments. cdata->num_elems and cdata->data->size are host-controlled. When a fragment's num_elems exceeds the remaining capacity (new_data_size - data_pos), memcpy_s() correctly refuses the copy and returns non-zero, but the following assert(!ret) then panics the DSP. A single malformed host SET request (small declared size, larger num_elems) is therefore enough to crash the firmware. Replace the assert with a graceful error path that frees and resets the in-progress blob state and returns the error to the IPC caller, mirroring the earlier IPC4 fix in ipc4_comp_data_blob_set() (commit 93be3b1aa). The destination size passed to memcpy_s() was already correct, so no bound is changed and legitimate transfers are unaffected. Found by libFuzzer IPC3/UBSan; all six reproducers now return cleanly and the ipc3 corpus (44828 runs) shows no regression. Signed-off-by: Tomasz Leman --- src/audio/data_blob.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/src/audio/data_blob.c b/src/audio/data_blob.c index 6996f4aa8bbc..a0f0cb0aa9bb 100644 --- a/src/audio/data_blob.c +++ b/src/audio/data_blob.c @@ -543,7 +543,15 @@ int comp_data_blob_set_cmd(struct comp_data_blob_handler *blob_handler, ret = memcpy_s((char *)blob_handler->data_new + blob_handler->data_pos, blob_handler->new_data_size - blob_handler->data_pos, cdata->data->data, cdata->num_elems); - assert(!ret); + if (ret) { + comp_err(blob_handler->dev, "memcpy_s failed with error %d", ret); + blob_handler->free(blob_handler, blob_handler->data_new); + blob_handler->data_new = NULL; + blob_handler->new_data_size = 0; + blob_handler->data_pos = 0; + blob_handler->data_ready = false; + return ret; + } blob_handler->data_pos += cdata->num_elems;